0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Critical Flowise Vulnerability Enables Full Server Compromise (infosecurity-magazine.com)

· 58d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Obsidian Security publishes PoC for CVE-2026-40933 in Flowise
  • Custom MCP tool with stdio transport executes commands without sandbox
  • Malicious chatflow import triggers RCE automatically on load
  • Official patch can be bypassed; latest version still vulnerable
  • Mitigation: disable stdio transport, switch to SSE

"A critical remote code execution vulnerability (CVE-2026-40933) in the open-source AI platform Flowise allows attackers to fully compromise self-hosted servers by importing a malicious workflow file. Obsidian Security published a proof-of-concept. The flaw resides in the Custom MCP tool with stdio transport, which executes commands without sandboxing. The official patch can be bypassed; the latest release remains vulnerable. Disabling stdio transport and switching to SSE is recommended."

#RCE vulnerability #Flowise AI platform #MCP protocol

Discussion Matrix

0 segments

no comments yet.